CRITICAL · Privilege Escalation — a real finding on the public argo/argo-cd Helm chart.
TL;DR: Rendering argo/argo-cd and scanning it with Bastion surfaced 19 escalation paths to cluster-admin — the headline being the argocd-application-controller ServiceAccount, bound to a ClusterRole granting verbs:[*] on resources:[*]. It doesn't reach cluster-admin; it is cluster-admin. On the same manifests, kube-score produced 107 findings and 0 about RBAC or escalation.
Escalation is a graph problem, not a per-resource checklist: Bastion builds the privilege graph and runs deterministic BFS to cluster-admin, the node, and secrets, citing file:line for every edge. It reports the path; it never walks it. The fix is to replace the wildcard rule with the specific resources the controller reconciles, and to gate pull requests with bastion diff --fail-on-new-path.